authenticate_ad_setup_finished.cfm in MediaCAST 8 and previous versions allows remote malicious users to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
inventivetec mediacast |